Practical Data-Leak Prevention for Legacy Applications in Enterprise Networks

Show full item record

Please use this identifier to cite or link to this item: http://hdl.handle.net/1853/36612

Title: Practical Data-Leak Prevention for Legacy Applications in Enterprise Networks
Author: Mundada, Yogesh ; Ramachandran, Anirudh ; Tariq, Mukarram Bin ; Feamster, Nick
Abstract: Organizations must control where private information spreads; this problem is referred to in the industry as data leak prevention. Commercial solutions for DLP are based on scanning content; these impose high overhead and are easily evaded. Research solutions for this problem, information flow control, require rewriting applications or running a custom operating system, which makes these approaches difficult to deploy. They also typically enforce information flow control on a single host, not across a network, making it difficult to implement an information flow control policy for a network of machines. This paper presents Pedigree, which enforces information flow control across a network for legacy applications. Pedigree allows enterprise administrators and users to associate a label with each file and process; a small, trusted module on the host uses these labels to determine whether two processes on the same host can communicate. When a process attempts to communicate across the network, Pedigree tracks these information flows and enforces information flow control either at end-hosts or at a network switch. Pedigree allows users and operators to specify network-wide information flow policies rather than having to specify and implement policies for each host. Enforcing information flow policies in the network allows Pedigree to operate in networks with heterogeneous devices and operating systems. We present the design and implementation of Pedigree, show that it can prevent data leaks, and investigate its feasibility and usability in common environments.
Description: Research area: Information Security & Cryptography Research topic: Network Security
Type: Technical Report
URI: http://hdl.handle.net/1853/36612
Date: 2011
Contributor: Georgia Institute of Technology. College of Computing
Georgia Institute of Technology. School of Computer Science
Relation: SCS Technical Report ; GT-CS-11-01
Publisher: Georgia Institute of Technology
Subject: Data leaks
Encryption
Information flow control
Information security
Label management
Network security

All materials in SMARTech are protected under U.S. Copyright Law and all rights are reserved, unless otherwise specifically indicated on or in the materials.

Files in this item

Files Size Format View
GT-CS-11-01.pdf 434.8Kb PDF View/ Open

This item appears in the following Collection(s)

Show full item record